Threat actors affiliated with China have been attributed to a fresh set of cyber espionage campaigns targeting government and law enforcement agencies across Southeast Asia throughout 2025. Check Point Research is tracking the previously undocumented activity cluster under the moniker Amaranth-Dragon, which it said shares links to the APT 41 ecosystem. Targeted countries include Cambodia,
Category: Asia Pacific
Asia Pacific, Global Security News
Intel sets sights on data center GPUs amid AI-driven infrastructure shifts
Intel is making a new push into GPUs, this time with a focus on data center workloads, as the chipmaker looks to reestablish itself in a market increasingly shaped by AI-driven demand and dominated by Nvidia. CEO Lip-Bu Tan said that after hiring a senior GPU architect, the company is working directly with customers to define…
Asia Pacific, china, Cybersecurity, Global Security News, Government, Threats, Uncategorized
Cantwell claims telecoms blocked release of Salt Typhoon report
More than a year after national security officials revealed that Chinese hackers had systematically infiltrated U.S. telecommunications networks, the top Senate Democrat on the committee overseeing the industry is calling for hearings with executives from the nation’s biggest telecom companies. In a public letter released Tuesday, Sen. Maria Cantwell, D-Wash., called for the CEOs of…
APT, Asia Pacific, Breaking News, Global Security News, hacking, malware, Security
Notepad++ infrastructure hack likely tied to China-nexus APT Lotus Blossom
Rapid7 researchers say the Notepad++ hosting breach is likely linked to the China-nexus Lotus Blossom APT group. Recently, the Notepad++ maintainer revealed that nation-state hackers compromised the hosting provider’s infrastructure, redirecting update traffic to malicious servers. The attack did not exploit flaws in Notepad++ code but intercepted updates before they reached users. “According to the…
Asia Pacific, Global Security News
Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group
A China-linked threat actor known as Lotus Blossom has been attributed with medium confidence to the recently discovered compromise of the infrastructure hosting Notepad++. The attack enabled the state-sponsored hacking group to deliver a previously undocumented backdoor codenamed Chrysalis to users of the open-source editor, according to new findings from Rapid7. The development comes shortly
APT, Asia Pacific, Authentication, Cybercrime, Global Security News, Research, Threats
China-based espionage group compromised Notepad++ for six months
A China-based threat group operating for almost two decades broke into the internal systems of Notepad++, an extremely popular open source-code editor, to spy on a select group of targeted users, researchers at Rapid7 said Monday. Don Ho, the author and maintainer of the open-source tool, said independent security researchers confirmed a China state-sponsored group…
APT, Asia Pacific, Authentication, Cybercrime, Global Security News, Research, Threats
China-based espionage group compromised Notepad++ for six months
A China-based threat group operating for almost two decades broke into the internal systems of Notepad++, an extremely popular open source-code editor, to spy on a select group of targeted users, researchers at Rapid7 said Monday. Don Ho, the author and maintainer of the open-source tool, said independent security researchers confirmed a China state-sponsored group…
Asia Pacific, Breaking News, Cybercrime, data breach, Global Security News, hacking, Security
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 82
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter KONNI Adopts AI to Generate PowerShell Backdoors Who Operates the Badbox 2.0 Botnet? Weaponized in China, Deployed in India: The SyncFuture Espionage Targeted Campaign Android Trojan Campaign Uses Hugging Face Hosting for RAT Payload…
Asia Pacific, Breaking News, Cybercrime, data breach, Global Security News, hacking, Security
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 82
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter KONNI Adopts AI to Generate PowerShell Backdoors Who Operates the Badbox 2.0 Botnet? Weaponized in China, Deployed in India: The SyncFuture Espionage Targeted Campaign Android Trojan Campaign Uses Hugging Face Hosting for RAT Payload…
Asia Pacific, Breaking News, Cybercrime, data breach, Global Security News, hacking, Security
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 82
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter KONNI Adopts AI to Generate PowerShell Backdoors Who Operates the Badbox 2.0 Botnet? Weaponized in China, Deployed in India: The SyncFuture Espionage Targeted Campaign Android Trojan Campaign Uses Hugging Face Hosting for RAT Payload…
Asia Pacific, Breaking News, Cybercrime, data breach, Global Security News, hacking, Security
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 82
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter KONNI Adopts AI to Generate PowerShell Backdoors Who Operates the Badbox 2.0 Botnet? Weaponized in China, Deployed in India: The SyncFuture Espionage Targeted Campaign Android Trojan Campaign Uses Hugging Face Hosting for RAT Payload…
Asia Pacific, Global Security News
20i Brings High-Performance Autoscaling to Asia-Pacific with New Singapore Data Centre Launch
20i, which describes itself as a leading global provider of managed hosting services, has announced the launch of its latest data centre in Singapore. The expansion marks a significant milestone in the company’s international growth, enabling customers across APAC to deploy autoscaling cloud hosting closer to their users.
Asia Pacific, Global Security News
20i Brings High-Performance Autoscaling to Asia-Pacific with New Singapore Data Centre Launch
20i, which describes itself as a leading global provider of managed hosting services, has announced the launch of its latest data centre in Singapore. The expansion marks a significant milestone in the company’s international growth, enabling customers across APAC to deploy autoscaling cloud hosting closer to their users.
Asia Pacific, Global Security News
20i Brings High-Performance Autoscaling to Asia-Pacific with New Singapore Data Centre Launch
20i, which describes itself as a leading global provider of managed hosting services, has announced the launch of its latest data centre in Singapore. The expansion marks a significant milestone in the company’s international growth, enabling customers across APAC to deploy autoscaling cloud hosting closer to their users.
Asia Pacific, Global Security News
Former Google Engineer Found Guilty of Stealing AI Secrets
Linwei Ding, a former Google engineer, has been found guilty of stealing trade secrets for China
Asia Pacific, Global Security News
HTX and Singtel Group deepen partnership to strengthen Singapore’s public safety capabilities
The partners signed a five-year agreement to accelerate the adoption of emerging technologies and scale frontline operational capabilities Home Team Science and Technology Agency HTX and Singtel have announced the renewal and expansion of their Strategic Partnership for Innovation (SPI) Master Agreement, “deepening their technological collaboration to strengthen Singapore’s public safety capabilities”.
Asia Pacific, Global Security News
HTX and Singtel Group deepen partnership to strengthen Singapore’s public safety capabilities
The partners signed a five-year agreement to accelerate the adoption of emerging technologies and scale frontline operational capabilities Home Team Science and Technology Agency HTX and Singtel have announced the renewal and expansion of their Strategic Partnership for Innovation (SPI) Master Agreement, “deepening their technological collaboration to strengthen Singapore’s public safety capabilities”.
Asia Pacific, Global Security News
HTX and Singtel Group deepen partnership to strengthen Singapore’s public safety capabilities
The partners signed a five-year agreement to accelerate the adoption of emerging technologies and scale frontline operational capabilities Home Team Science and Technology Agency HTX and Singtel have announced the renewal and expansion of their Strategic Partnership for Innovation (SPI) Master Agreement, “deepening their technological collaboration to strengthen Singapore’s public safety capabilities”.
Asia Pacific, Global Security News
AI’s Fundraising Frenzy Continues
Plus, China’s EV victory, 7 reasons teens say no to AI, trouble with the Nvidia-OpenAI megadeal and how AI is coming for Apple’s profit margins, in this edition of the Technology newsletter.
Asia Pacific, china, Cybercrime, Cybersecurity, Global Security News, Threats
Google’s disruption rips millions out of devices out of malicious network
Millions of devices used as proxies by cybercriminals, espionage groups and data thieves have been removed from circulation following Google’s disruption of IPIDEA, a China-based residential proxy network. The reduction in available proxy devices came after Google’s Threat Intelligence Group used legal action and intelligence sharing to target the company’s domain infrastructure, Google said in…
Asia Pacific, Global Security News
China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware
Cybersecurity researchers have discovered a new campaign attributed to a China-linked threat actor known as UAT-8099 that took place between late 2025 and early 2026. The activity, discovered by Cisco Talos, has targeted vulnerable Internet Information Services (IIS) servers located across Asia, but with a specific focus on targets in Thailand and Vietnam. The scale…
AI, Artificial Intelligence (AI), Asia Pacific, china, Commentary, Global Security News
Cybersecurity can be America’s secret weapon in the AI race
Much of the public conversation about the U.S. “winning” the AI race with China centers exclusively on each nations’ ability to develop and implement leading AI models. But amid escalating cyber threats, the rising reality is that the race will not be won merely by the nation with the most advanced technology, but the one…
Asia Pacific, Global Security News
Ex-Google Engineer Convicted for Stealing 2,000 AI Trade Secrets for China Startup
A former Google engineer accused of stealing thousands of the company’s confidential documents to build a startup in China has been convicted in the U.S., the Department of Justice (DoJ) announced Thursday. Linwei Ding (aka Leon Ding), 38, was convicted by a federal jury on seven counts of economic espionage and seven counts of theft…
Asia Pacific, Global Security News, Vendor Leadership & Partner Programs
Zebra Technologies Names New APAC Leaders
Zebra Technologies has announced leadership changes across the Asia Pacific (APAC) region, appointing Tom Christodoulou as Sales Vice President for Australia & New Zealand (ANZ), Southeast Asia (SEA), and Korea; and naming Christanto Suryadarma to the newly created role of Head of Partnerships for APAC. Christodoulou takes on expanded territory in APAC According to the…
Asia Pacific, Global Security News
Mustang Panda Deploys Updated COOLCLIENT Backdoor in Government Cyber Attacks
Threat actors with ties to China have been observed using an updated version of a backdoor called COOLCLIENT in cyber espionage attacks in 2025 to facilitate comprehensive data theft from infected endpoints. The activity has been attributed to Mustang Panda (aka Earth Preta, Fireant, HoneyMyte, Polaris, and Twill Typhoon) with the intrusions primarily directed against…
Asia Pacific, Global Security News
Google Warns of Active Exploitation of WinRAR Vulnerability CVE-2025-8088
Google on Tuesday revealed that multiple threat actors, including nation-state adversaries and financially motivated groups, are exploiting a now-patched critical security flaw in RARLAB WinRAR to establish initial access and deploy a diverse array of payloads. “Discovered and patched in July 2025, government-backed threat actors linked to Russia and China as well as financially motivated
Asia Pacific, Global Security News
PeckBirdy Framework Tied to China-Aligned Cyber Campaigns
PeckBirdy command-and-control framework targeting gambling, government sectors in Asia since 2023 has been linked to China-aligned APTs
Asia Pacific, Cybersecurity, Cybersecurity and Infrastructure Security Agency, encryption, Global Security News, Government, Technology
CISA publishes a post-quantum shopping list for agencies. Security professionals aren’t sold
The Cybersecurity and Infrastructure Security Agency is hoping to guide federal agencies through the murky process of updating their technology stack with quantum-resistant encryption. On Jan. 23, the agency released a list of different IT software and hardware products that are commonly purchased by the federal government and use cryptographic algorithms for encryption or authentication.…
Asia Pacific, Breadcrumbs, Global Security News, Internet of Things (IoT), Web Fraud 2.0
Who Operates the Badbox 2.0 Botnet?
The cybercriminals in control of Kimwolf — a disruptive botnet that has infected more than 2 million devices — recently shared a screenshot indicating they’d compromised the control panel for Badbox 2.0, a vast China-based botnet powered by malicious software that comes pre-installed on many Android TV streaming boxes. Both the FBI and Google say…
Asia Pacific, Global Security News
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code
Cybersecurity researchers have discovered two malicious Microsoft Visual Studio Code (VS Code) extensions that are advertised as artificial intelligence (AI)-powered coding assistants, but also harbor covert functionality to siphon developer data to China-based servers. The extensions, which have 1.5 million combined installs and are still available for download from the official Visual Studio
Asia Pacific, Global Security News, Trend Micro Research : APT & Targeted Attacks, Trend Micro Research : Articles, News, Reports, Trend Micro Research : Research
PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups
PeckBirdy is a sophisticated JScript-based C&C framework used by China-aligned APT groups to exploit LOLBins across multiple environments, delivering advanced backdoors to target gambling industries and Asian government entities.
Artificial Intelligence, Asia Pacific, Global Security News, Microsoft, Security
Malicious AI extensions on VSCode Marketplace steal developer data
Two malicious extensions in Microsoft’s Visual Studio Code (VSCode) Marketplace that were collectively installed 1.5 million times, exfiltrate developer data to China-based servers. […]
Asia Pacific, Global Security News
Risky Chinese Electric Buses Spark Aussie Gov’t Review
Deployed across Australia and Europe, China’s electric buses are vulnerable to cybercriminals and sport a virtual kill switch the Chinese state could activate.
Asia Pacific, critical-infrastructure-security, Global Security News
EU-Kommission will Huawei und ZTE aus Netzen verbannen
Die EU-Kommission will chinesische Hersteller wie Huawei und ZTE aus europäischen Mobilfunknetzen verbannen, um die Cybersicherheit zu verbessern. Jacek Wojnarowski – shutterstock.com Die EU-Kommission will umstrittene Anbieter von Netzwerktechnik künftig in Deutschland und anderen EU-Staaten verbieten können. Bei dem Vorschlag dürfte es insbesondere um chinesische Technologiefirmen wie Huawei und ZTE gehen. Hintergrund ist die Sorge…
AI, Asia Pacific, Cybersecurity, Global Security News, Policy, Research, Uncategorized
HackerOne rolls out industry framework to support ‘good faith’ AI research
Four years ago, the Department of Justice announced it would no longer seek criminal charges against independent and third-party security researchers for “good faith” security research under the Computer Fraud and Abuse Act. Now, a prominent bug bounty platform is attempting to build a framework for industry to offer similar protections to researchers who study…
Asia Pacific, Global Security News, Internet of Things (IoT), Latest Warnings, The Coming Storm, Web Fraud 2.0
Kimwolf Botnet Lurking in Corporate, Govt. Networks
A new Internet-of-Things (IoT) botnet called Kimwolf has spread to more than 2 million devices, forcing infected systems to participate in massive distributed denial-of-service (DDoS) attacks and to relay other malicious and abusive Internet traffic. Kimwolf’s ability to scan the local networks of compromised systems for other IoT devices to infect makes it a sobering…
Asia Pacific, Breaking News, Crypto, cyber crime, Cybercrime, Global Security News, hacking
Telegram-based illicit billionaire marketplace Tudou Guarantee stopped transactions
Major Telegram-based illicit marketplace Tudou Guarantee appears to be shutting down its operations, according to Elliptic. Blockchain cybersecurity firm Elliptic reports that Tudou Guarantee, a major Telegram-based illicit marketplace in Southeast Asia, has stopped transactions in its public groups after handling over $12 billion. The researchers noted that other services still run, so a full…
Asia Pacific, Global Security News
Rare-Earth Magnet Maker Raises $215 Million to Amp Up U.S. Supply
The investment in Texas-based Noveon comes as the U.S. pushes to develop domestic sources of a vital electronics component that China has under a chokehold.
Asia Pacific, Global Security News
China-Linked APT Exploits Sitecore Zero-Day in Attacks on American Critical Infrastructure
A threat actor likely aligned with China has been observed targeting critical infrastructure sectors in North America since at least last year. Cisco Talos, which is tracking the activity under the name UAT-8837, assessed it to be a China-nexus advanced persistent threat (APT) actor with medium confidence based on tactical overlaps with other campaigns mounted…
Asia Pacific, Global Security News
Cisco Patches Zero-Day RCE Exploited by China-Linked APT in Secure Email Gateways
Cisco on Thursday released security updates for a maximum-severity security flaw impacting Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, nearly a month after the company disclosed that it had been exploited as a zero-day by a China-nexus advanced persistent threat (APT) actor codenamed UAT-9686. The vulnerability, tracked…
Asia Pacific, Global Security News
Chinese AI Developers Say They Can’t Beat America Without Better Chips
Companies in China jostle for access to Nvidia’s latest Rubin lineup while better-funded U.S. competitors are first in line.
Asia Pacific, Breaking News, china, Global Security News, intelligence, Security
China bans U.S. and Israeli cybersecurity software over security concerns
China has told domestic firms to stop using U.S. and Israeli cybersecurity software, citing national security concerns amid rising tech tensions. Reuters reported that China has ordered domestic companies to stop using cybersecurity solutions from more than a dozen U.S. and Israeli firms, citing national security risks. Tensions remain high over China’s push in semiconductors…
Asia Pacific, Global Security News
Yea or nay: Will Nvidia H200 chips go to China?
In what appears to be a case of diplomatic mind games in action, one day after the US government issued a regulation clearing the way for Nvidia to sell its H200 artificial intelligence processors to Chinese companies on a case-by-case basis, a published report has revealed Chinese custom officers have been told not to let…
Asia Pacific, Global Security News
Iran’s partial internet shutdown may be a windfall for cybersecurity intel
The near-total internet blackout imposed by the Iranian government starting January 8, reportedly due to a crackdown on protesters, may offer a rare opportunity to SOC staffers and other cybersecurity analysts, briefly allowing all government traffic sources to be identified and digitally fingerprinted, a massive help in tracking Iranian state actors. Among global malicious state…
Asia Pacific, Global Security News
Nozomi Networks Announces Major Investment in Singapore
COMPANY ANNOUNCEMENT: Industrial cyber security leader unveils new regional headquarters in Singapore to meet rising demand across the Asia Pacific & Japan Region
Artificial Intelligence, Generative AI, Asia Pacific, Global Security News
Chinese AI firm trains state-of-the-art model entirely on Huawei chips
Chinese company Zhipu AI has trained image generation model entirely on Huawei processors, demonstrating that Chinese firms can build competitive AI systems without access to advanced Western chips. The model, released on Tuesday, marks the first time a state-of-the-art multimodal model completed its full training cycle on Chinese-made chips, Zhipu said in a statement. The…
Asia Pacific, Congress, Cybersecurity and Infrastructure Security Agency (CISA), Global Security News, Government, Policy, Workforce
Sean Plankey re-nominated to lead CISA
President Donald Trump re-nominated Sean Plankey to lead the Cybersecurity and Infrastructure Security Agency on Tuesday, after Plankey’s bid for the position ended last year stuck in the Senate. It’s not clear whether or how Plankey’s resubmitted nomination will overcome the hurdles that left many observers convinced his chance of becoming CISA director had likely…
AI, Asia Pacific, Cybersecurity, Global Security News, Government, Policy, Technology
CESER chief touts AI projects as congressional Dems point to federal cuts
A Trump administration official endorsed a slate of congressional bills Tuesday targeting cybersecurity in the energy sector while touting the office’s new emphasis on AI-driven cyber defenses. Meanwhile, Democratic members repeatedly pressed him over the cybersecurity and reliability impacts from thousands of job cuts that have taken place at the Department of Energy over the…
Asia Pacific, Global Security News, Laws and Regulations, Mobile, Security
India may require smartphone manufacturers to disclose source code
According to information provided to Reuters, India is considering a new security requirement that could require smartphone manufacturers to share their source code with the state. The proposal is part of a package of 83 security standards designed to strengthen protection against data breaches and fraud. The requirements include that manufacturers must allow Indian authorities…
Asia Pacific, Global Security News
Apple confirms ‘multi-year’ Google Gemini AI partnership
Apple has confirmed speculation that it will work with Google’s Gemini models to help power new artificial intelligence (AI) features across its products, including Siri, in a multi-year partnership expected to begin later this year. The company confirmed the move to CNBC’s Jim Cramer in this statement: “After careful evaluation, we determined that Google’s technology provides the most capable foundation…
Asia Pacific, Cyberattacks, Cybercrime, Security, Global Security News
Iran-linked MuddyWater APT deploys Rust-based implant in latest campaign
Iran-linked advanced persistent threat group MuddyWater has deployed a Rust-based implant in an ongoing espionage campaign targeting organizations in Israel and other Middle Eastern countries, according to CloudSEK. CloudSEK’s TRIAD team said it identified the spear-phishing campaign targeting diplomatic, maritime, financial, and telecom entities across the Middle East. The campaign uses icon spoofing and malicious…
APT, Asia Pacific, Breaking News, Global Security News, hacking, intelligence, malware
China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware
China-linked UAT-7290 has targeted South Asia and Southeastern Europe since 2022, conducting espionage and deploying RushDrop, DriveSwitch, and SilentRaid. China-linked threat actor UAT-7290 has conducted espionage attacks since at least 2022, targeting South Asia and Southeastern Europe. UAT-7290 primarily targets telecom providers, it conducts espionage by deeply embedding in victim networks and also operates Operational…
APT, Asia Pacific, Breaking News, Global Security News, hacking, intelligence, malware
China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware
China-linked UAT-7290 has targeted South Asia and Southeastern Europe since 2022, conducting espionage and deploying RushDrop, DriveSwitch, and SilentRaid. China-linked threat actor UAT-7290 has conducted espionage attacks since at least 2022, targeting South Asia and Southeastern Europe. UAT-7290 primarily targets telecom providers, it conducts espionage by deeply embedding in victim networks and also operates Operational…
APT, Asia Pacific, Breaking News, Global Security News, hacking, intelligence, malware
China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware
China-linked UAT-7290 has targeted South Asia and Southeastern Europe since 2022, conducting espionage and deploying RushDrop, DriveSwitch, and SilentRaid. China-linked threat actor UAT-7290 has conducted espionage attacks since at least 2022, targeting South Asia and Southeastern Europe. UAT-7290 primarily targets telecom providers, it conducts espionage by deeply embedding in victim networks and also operates Operational…
APT, Asia Pacific, Breaking News, Global Security News, hacking, intelligence, malware
China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware
China-linked UAT-7290 has targeted South Asia and Southeastern Europe since 2022, conducting espionage and deploying RushDrop, DriveSwitch, and SilentRaid. China-linked threat actor UAT-7290 has conducted espionage attacks since at least 2022, targeting South Asia and Southeastern Europe. UAT-7290 primarily targets telecom providers, it conducts espionage by deeply embedding in victim networks and also operates Operational…
APT, Asia Pacific, Breaking News, Global Security News, hacking, intelligence, malware
China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware
China-linked UAT-7290 has targeted South Asia and Southeastern Europe since 2022, conducting espionage and deploying RushDrop, DriveSwitch, and SilentRaid. China-linked threat actor UAT-7290 has conducted espionage attacks since at least 2022, targeting South Asia and Southeastern Europe. UAT-7290 primarily targets telecom providers, it conducts espionage by deeply embedding in victim networks and also operates Operational…
APT, Asia Pacific, Breaking News, Global Security News, hacking, intelligence, malware
China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware
China-linked UAT-7290 has targeted South Asia and Southeastern Europe since 2022, conducting espionage and deploying RushDrop, DriveSwitch, and SilentRaid. China-linked threat actor UAT-7290 has conducted espionage attacks since at least 2022, targeting South Asia and Southeastern Europe. UAT-7290 primarily targets telecom providers, it conducts espionage by deeply embedding in victim networks and also operates Operational…
APT, Asia Pacific, Breaking News, Global Security News, hacking, intelligence, malware
China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware
China-linked UAT-7290 has targeted South Asia and Southeastern Europe since 2022, conducting espionage and deploying RushDrop, DriveSwitch, and SilentRaid. China-linked threat actor UAT-7290 has conducted espionage attacks since at least 2022, targeting South Asia and Southeastern Europe. UAT-7290 primarily targets telecom providers, it conducts espionage by deeply embedding in victim networks and also operates Operational…
APT, Asia Pacific, Breaking News, Global Security News, hacking, intelligence, malware
China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware
China-linked UAT-7290 has targeted South Asia and Southeastern Europe since 2022, conducting espionage and deploying RushDrop, DriveSwitch, and SilentRaid. China-linked threat actor UAT-7290 has conducted espionage attacks since at least 2022, targeting South Asia and Southeastern Europe. UAT-7290 primarily targets telecom providers, it conducts espionage by deeply embedding in victim networks and also operates Operational…
APT, Asia Pacific, Breaking News, Global Security News, hacking, intelligence, malware
China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware
China-linked UAT-7290 has targeted South Asia and Southeastern Europe since 2022, conducting espionage and deploying RushDrop, DriveSwitch, and SilentRaid. China-linked threat actor UAT-7290 has conducted espionage attacks since at least 2022, targeting South Asia and Southeastern Europe. UAT-7290 primarily targets telecom providers, it conducts espionage by deeply embedding in victim networks and also operates Operational…
APT, Asia Pacific, Breaking News, Global Security News, hacking, intelligence, malware
China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware
China-linked UAT-7290 has targeted South Asia and Southeastern Europe since 2022, conducting espionage and deploying RushDrop, DriveSwitch, and SilentRaid. China-linked threat actor UAT-7290 has conducted espionage attacks since at least 2022, targeting South Asia and Southeastern Europe. UAT-7290 primarily targets telecom providers, it conducts espionage by deeply embedding in victim networks and also operates Operational…
APT, Asia Pacific, Breaking News, Global Security News, hacking, intelligence, malware
China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware
China-linked UAT-7290 has targeted South Asia and Southeastern Europe since 2022, conducting espionage and deploying RushDrop, DriveSwitch, and SilentRaid. China-linked threat actor UAT-7290 has conducted espionage attacks since at least 2022, targeting South Asia and Southeastern Europe. UAT-7290 primarily targets telecom providers, it conducts espionage by deeply embedding in victim networks and also operates Operational…
APT, Asia Pacific, Breaking News, Global Security News, hacking, intelligence, malware
China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware
China-linked UAT-7290 has targeted South Asia and Southeastern Europe since 2022, conducting espionage and deploying RushDrop, DriveSwitch, and SilentRaid. China-linked threat actor UAT-7290 has conducted espionage attacks since at least 2022, targeting South Asia and Southeastern Europe. UAT-7290 primarily targets telecom providers, it conducts espionage by deeply embedding in victim networks and also operates Operational…
Asia Pacific, Global Security News
China-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes
A China-nexus threat actor known as UAT-7290 has been attributed to espionage-focused intrusions against entities in South Asia and Southeastern Europe. The activity cluster, which has been active since at least 2022, primarily focuses on extensive technical reconnaissance of target organizations before initiating attacks, ultimately leading to the deployment of malware families such as RushDrop
Asia Pacific, Breaking News, china, Cyber warfare, Global Security News, intelligence, Security
China-linked groups intensify attacks on Taiwan’s critical infrastructure, NSB warns
Taiwan says China-linked cyberattacks on its energy sector rose tenfold in 2025, hitting critical infrastructure across nine sectors, with total incidents up 6%. Taiwan reports China-linked cyberattacks on its energy sector surged tenfold in 2025, targeting critical infrastructure across nine sectors, with total incidents up 6% YoY. Taiwan’s National Security Bureau (NSB) reports China launched…
Asia Pacific, china, critical infrastructure, energy, Foundation for Defense of Democracies, Geopolitics, Global Security News
Taiwan blames Chinese ‘cyber army’ for rise in millions of daily intrusion attempts
Taiwan endured a year-long intensified cyber offensive from China in 2025, that targeted the government and critical infrastructure — with an increasing focus on the energy and hospital sectors, according to a Taiwan government analysis published this week. Cyberattacks from China rose 6% compared to 2024, the National Security Bureau analysis concluded. Every major sector…
Asia Pacific, Global Security News
China intensifies Cyber-Attacks on Taiwan as Energy Sector Sees Tenfold Spike
Taiwan recorded an average of 2.63 million cyber intrusion attempts to it critical infrastructure per day coming from China in 2025
Asia Pacific, Global Security News
Chinese authorities scrutinize Meta’s purchase of AI startup Manus
Last week, news broke that Meta is buying Chinese AI startup Manus for around $2 billion. The company is known for its AI agent that can handle everything from job interviews to stock analysis. Meta plans to integrate Manus’ AI agent into its own products. Now, the Financial Times reports that China’s Ministry of Commerce…
Asia Pacific, Global Security News
Automated data poisoning proposed as a solution for AI theft threat
Researchers have developed a tool that they say can make stolen high-value proprietary data used in AI systems useless, a solution that CSOs may have to adopt to protect their sophisticated large language models (LLMs). The technique, created by researchers from universities in China and Singapore, is to inject plausible but false data into what’s…
Asia Pacific, Global Security News, Government, Security
Taiwan says China’s attacks on its energy sector increased tenfold
The National Security Bureau in Taiwan says that China’s attacks on the country’s energy sector increased tenfold in 2025 compared to the previous year. […]
Asia Pacific, Global Security News
Nvidia CEO Says Chinese Demand for Its AI Chips Is ‘Quite High’
“H200s are flowing” since the company won White House approval to sell the processor in China, Jensen Huang said.
Asia Pacific, Global Security News
Samsung to double number of mobile AI devices in 2026
Samsung plans to double the number of mobile devices with Galaxy AI in 2026, from 400 to 800 million, Reuters reports. The AI features are largely powered by Google’s Gemini model, as well as Samsung’s own AI assistant Bixby. Samsung co-CEO T.M. Roh says the goal is to quickly introduce AI into all products, features…
Artificial Intelligence, Generative AI, Asia Pacific, Global Security News
Deepseek says new method can train AI more efficiently and cheaply
Chinese AI company Deepseek has unveiled a new training method, Manifold-Constrained Hyper-Connections (mHC), which will make it possible to train large language models more efficiently and at lower cost, reports the South China Morning Post. The method is a further development of so-called Hyper-Connections, which was originally developed by Bytedance in 2024. That technology, in…
Asia Pacific, Breaking News, Global Security News, hacking, hacking news, Security
Singapore CSA warns of maximun severity SmarterMail RCE flaw
Singapore’s CSA warns of CVE-2025-52691, a critical SmarterMail flaw enabling unauthenticated remote code execution via arbitrary file upload. Singapore’s Cyber Security Agency of Singapore (CSA) warns of a maximum severity flaw, tracked as CVE-2025-52691 (CVSS score of 10.0), in SmarterMail. The vulnerability enables unauthenticated remote code execution via arbitrary file upload. “Successful exploitation of the…
Asia Pacific, Global Security News, Mergers & Acquisitions
Meta Buys Manus to Turn AI Agents Into a Business
Zuck has struck again. Meta Platforms has acquired Manus, a Singapore-based startup developing general-purpose AI agents, in a deal valued at more than $2 billion. The acquisition caps off a breakneck busy year of AI dealmaking for Meta. It highlights the overall goal of building AI products that are already generating real revenue, not just…
Asia Pacific, Global Security News
How Meta’s Newest Acquisition Target Got Around Worries Over Its Ties to China
The $2.5 billion deal could herald a new era for China-linked AI companies and U.S. investors.
Asia Pacific, Global Security News
CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution
The Cyber Security Agency of Singapore (CSA) has issued a bulletin warning of a maximum-severity security flaw in SmarterTools SmarterMail email software that could be exploited to achieve remote code execution. The vulnerability, tracked as CVE-2025-52691, carries a CVSS score of 10.0. It relates to a case of arbitrary file upload that could enable code…
APT, Asia Pacific, Breaking News, Global Security News, intelligence, malware, Security
Mustang Panda deploys ToneShell via signed kernel-mode rootkit driver
China-linked APT Mustang Panda used a signed kernel-mode rootkit driver to load shellcode and deploy its ToneShell backdoor. China-linked APT Mustang Panda (aka Hive0154, HoneyMyte, Camaro Dragon, RedDelta or Bronze President) was observed using a signed kernel-mode rootkit driver with embedded shellcode to deploy its ToneShell backdoor. Mustang Panda has been active since at least 2012, targeting American and European entities such as…
A Little Sunshine, Asia Pacific, Funnull, Global Security News, HeartSender
Happy 16th Birthday, KrebsOnSecurity.com!
KrebsOnSecurity.com celebrates its 16th anniversary today! A huge “thank you” to all of our readers — newcomers, long-timers and drive-by critics alike. Your engagement this past year here has been tremendous and truly a salve on a handful of dark days. Happily, comeuppance was a strong theme running through our coverage in 2025, with a…
Asia Pacific, Global Security News
The AI Scorecard: How the U.S. Built a Lead—and Could Lose It to China
If the U.S.-China artificial-intelligence rivalry were a football game, America would be leading at halftime—but it just made a risky trade.
APT, Asia Pacific, china, Global Security News, intelligence, malware, Security
Evasive Panda cyberespionage campaign uses DNS poisoning to install MgBot backdoor
China-linked APT Evasive Panda used DNS poisoning to deliver the MgBot backdoor in targeted cyber-espionage attacks in Türkiye, China, and India. Kaspersky researchers spotted the China-linked APT group Evasive Panda (aka Daggerfly, Bronze Highland, and StormBamboo) running a targeted cyber-espionage campaign using DNS poisoning to deliver the MgBot backdoor against victims in Türkiye, China, and…
Asia Pacific, Global Security News
Our Tech Columnists’ Annual Predictions: Folding iPhones, Mind-Reading Tech, EV Supercars
Plus, teen AI founders, humanoid-robot hype, Nvidia’s fresh Groq deal, China’s AI fears and more, in this edition of the Technology newsletter.
Asia Pacific, Global Security News
China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware
A China-linked advanced persistent threat (APT) group has been attributed to a highly-targeted cyber espionage campaign in which the adversary poisoned Domain Name System (DNS) requests to deliver its signature MgBot backdoor in attacks targeting victims in Türkiye, China, and India. The activity, Kaspersky said, was observed between November 2022 and November 2024. It has…
AI, Artificial Intelligence (AI), Asia Pacific, Cybersecurity, Global Security News, Government, Technology
NIST, MITRE announce $20 million research effort on AI cybersecurity
The National Institute of Standards and Technology announced that it will partner with The MITRE Corporation on a $20 million project to stand up two new research centers focused on artificial intelligence, including how the technology may impact cybersecurity for U.S. critical infrastructure. On Monday, the agency said one center will focus on advanced manufacturing…
Asia Pacific, Global Security News
Apple appears set to begin iPhone 18 (test) production soon
Something that appears to have started earlier than ever before, Apple is allegedly already test manufacturing of the next model of its basic smartphone, the iPhone 18. This news follows speculation from multiple sources, including legendary Apple analyst Ming-Chi Kuo, who said, “Apple is expected to begin trial production of the iPhone 18 series in January, which…
Asia Pacific, Global Security News, Technology, Voices
Anti-Palestinian Billionaires Will Now Control What TikTok Users See
TikTok’s Chinese owner ByteDance has signed binding agreements with U.S. and global investors to operate its business in America, it told employees on Dec. 18, 2025. Photo: Qin Zihang/VCG via Getty Images The TikTok deal announced on Thursday poses a fundamental threat to free and honest discourse about Israel’s ongoing genocide of Palestinians in Gaza. Under…
Asia Pacific, Global Security News
Why Macs are good for business
Earlier this year, Omdia told us the MacBook Air had become the world’s most popular business laptop. With that in mind, I spoke with Apple Director for Mac Product Marketing Colleen Novielli, about why she thinks this is the case. The move in recent years to Apple Silicon in Macs delivered a major boost to the platform. Not only did…
Asia Pacific, Global Security News
LongNosedGoblin Caught Snooping on Asian Governments
New China-aligned APT group is deploying Group Policy to sniff through government networks across Southeast Asia and Japan.
Asia Pacific, Global Security News
China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware
A previously undocumented China-aligned threat cluster dubbed LongNosedGoblin has been attributed to a series of cyber attacks targeting governmental entities in Southeast Asia and Japan. The end goal of these attacks is cyber espionage, Slovak cybersecurity company ESET said in a report published today. The threat activity cluster has been assessed to be active since…
alibaba, Asia Pacific, Geopolitics, Global Security News, Government, Policy, Technology
Senate Intel chair urges national cyber director to safeguard against open-source software threats
Senate Intelligence Committee Chairman Tom Cotton is raising the spectre of foreign adversaries playing too heavy a role in open-source software, and asking the national cyber director to counter the risks. The Oklahoma Republican wrote to National Cyber Director Sean Cairncross Thursday, saying he was concerned about reports that “state-sponsored software developers and cyber espionage…
Asia Pacific, Global Security News
Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances
Cisco has alerted users of a maximum-severity zero-day flaw in Cisco AsyncOS software that has been actively exploited by a China-nexus advanced persistent threat (APT) actor codenamed UAT-9686 in attacks targeting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. The networking equipment major said it became aware of the intrusion campaign on…
Asia Pacific, Global Security News
Server revenue hits record in Q3
The server market hit a record in the third quarter of 2025 with revenues of $ 112.4 billion, according to IDC. That’s a whopping 61 percent increase compared to the same period in 2024. Sales of x86 servers grew 32.8 percent to $76.3 billion, while sales of non-x86 servers rose 192.7 percent to $36.2 billion.…
Asia Pacific, Global Security News
Chinese Ink Dragon Group Hides in European Government Networks
China’s Ink Dragon is using European government networks to hide its espionage activity
Andrew Garbarino, Artificial Intelligence (AI), Asia Pacific, china, Cybersecurity and Infrastructure Security Agency (CISA), Global Security News, Policy
Key lawmaker says Congress likely to kick can down road on cyber information sharing law
With a little more than a month left before a foundational cyber threat information sharing law expires for a second time, Congress might have to do another short-term extension as negotiations on a longer deal aren’t yet bearing fruit, a key lawmaker said Tuesday. House Homeland Security Chairman Andrew Garbarino, R-N.Y., said the problem with…
Asia Pacific, Global Security News
The mistold story of a software failure that grounded 6,000 jets
“You should fly. It’s safer.” It’s a fact. The odds are in your favor when compared to auto travel. It’s not even close, we often remind the flight-fearing traveler. Yet two of the smartest people I have known refuse to fly despite agreeing with this statistic. I think of them every time I board a…
Asia Pacific, Global Security News
ChatGPT and a Murder-Suicide
Plus, bad AI gadgets, trusting machine decision-making, China’s data-center power play and Sam Altman’s ‘Code Red’
Asia Pacific, Global Security News
Trump’s OK of AI Chip Sales in China Called ‘Dangerous’ by Senate Democrats
Sens. Elizabeth Warren, Chuck Schumer and other lawmakers said allowing sales of Nvidia’s H200 processors in China undoes past U.S. containment efforts
Asia Pacific, Global Security News
Trump’s OK of AI Chip Sales in China Called ‘Dangerous’ by Senate Democrats
Sens. Elizabeth Warren, Chuck Schumer and other lawmakers said allowing sales of Nvidia’s H200 processors in China undoes past U.S. containment efforts
Asia Pacific, Breaking News, Global Security News, hacking, hacking news, information security news, Security
Notepad++ fixed updater bugs that allowed malicious update hijacking
Notepad++ addressed an updater vulnerability that allows attackers hijack update traffic due to weak file authentication. Notepad++ addressed a flaw in its updater that allowed attackers to hijack update traffic due to improper authentication of update files in earlier versions. The popular security researcher Kevin Beaumont first reported that several Notepad++ users faced security incidents.…
Asia Pacific, Breaking News, Global Security News, hacking, information security news, IT Information Security, malware
Elastic detects stealthy NANOREMOTE malware using Google Drive as C2
Elastic found a new Windows backdoor, NANOREMOTE, similar to FINALDRAFT/REF7707, using the Google Drive API for C2. Elastic Security Labs researchers uncovered NANOREMOTE, a new Windows backdoor that uses the Google Drive API for C2. Elastic says it shares code with the FINALDRAFT (Squidoor) implant, which uses Microsoft Graph API and is linked to threat…
